6.8

CVE-2019-5516

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x before 11.0.3 and 10.x before 10.1.6) updates address an out-of-bounds vulnerability with the vertex shader functionality. Exploitation of this issue requires an attacker to have access to a virtual machine with 3D graphics enabled. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on their own VM. The workaround for this issue involves disabling the 3D-acceleration feature. This feature is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareFusion Version >= 10.0.0 < 10.1.6
VMwareFusion Version >= 11.0.0 < 11.0.3
VMwareWorkstation Version >= 14.0.0 < 14.1.6
VMwareWorkstation Version >= 15.0.0 < 15.0.3
VMwareESXi Version6.5 Update-
VMwareESXi Version6.5 Update650-201701001
VMwareESXi Version6.5 Update650-201703001
VMwareESXi Version6.5 Update650-201703002
VMwareESXi Version6.5 Update650-201704001
VMwareESXi Version6.5 Update650-201707101
VMwareESXi Version6.5 Update650-201707102
VMwareESXi Version6.5 Update650-201707103
VMwareESXi Version6.5 Update650-201707201
VMwareESXi Version6.5 Update650-201707202
VMwareESXi Version6.5 Update650-201707203
VMwareESXi Version6.5 Update650-201707204
VMwareESXi Version6.5 Update650-201707205
VMwareESXi Version6.5 Update650-201707206
VMwareESXi Version6.5 Update650-201707207
VMwareESXi Version6.5 Update650-201707208
VMwareESXi Version6.5 Update650-201707209
VMwareESXi Version6.5 Update650-201707210
VMwareESXi Version6.5 Update650-201707211
VMwareESXi Version6.5 Update650-201707212
VMwareESXi Version6.5 Update650-201707213
VMwareESXi Version6.5 Update650-201707214
VMwareESXi Version6.5 Update650-201707215
VMwareESXi Version6.5 Update650-201707216
VMwareESXi Version6.5 Update650-201707217
VMwareESXi Version6.5 Update650-201707218
VMwareESXi Version6.5 Update650-201707219
VMwareESXi Version6.5 Update650-201707220
VMwareESXi Version6.5 Update650-201707221
VMwareESXi Version6.5 Update650-201710001
VMwareESXi Version6.5 Update650-201712001
VMwareESXi Version6.5 Update650-201803001
VMwareESXi Version6.5 Update650-201806001
VMwareESXi Version6.5 Update650-201808001
VMwareESXi Version6.5 Update650-201810001
VMwareESXi Version6.5 Update650-201810002
VMwareESXi Version6.5 Update650-201811001
VMwareESXi Version6.5 Update650-201811002
VMwareESXi Version6.5 Update650-201811301
VMwareESXi Version6.5 Update650-201901001
VMwareESXi Version6.7 Update-
VMwareESXi Version6.7 Update670-201806001
VMwareESXi Version6.7 Update670-201807001
VMwareESXi Version6.7 Update670-201808001
VMwareESXi Version6.7 Update670-201810001
VMwareESXi Version6.7 Update670-201810101
VMwareESXi Version6.7 Update670-201810102
VMwareESXi Version6.7 Update670-201810103
VMwareESXi Version6.7 Update670-201810201
VMwareESXi Version6.7 Update670-201810202
VMwareESXi Version6.7 Update670-201810203
VMwareESXi Version6.7 Update670-201810204
VMwareESXi Version6.7 Update670-201810205
VMwareESXi Version6.7 Update670-201810206
VMwareESXi Version6.7 Update670-201810207
VMwareESXi Version6.7 Update670-201810208
VMwareESXi Version6.7 Update670-201810209
VMwareESXi Version6.7 Update670-201810210
VMwareESXi Version6.7 Update670-201810211
VMwareESXi Version6.7 Update670-201810212
VMwareESXi Version6.7 Update670-201810213
VMwareESXi Version6.7 Update670-201810214
VMwareESXi Version6.7 Update670-201810215
VMwareESXi Version6.7 Update670-201810216
VMwareESXi Version6.7 Update670-201810217
VMwareESXi Version6.7 Update670-201810218
VMwareESXi Version6.7 Update670-201810219
VMwareESXi Version6.7 Update670-201810220
VMwareESXi Version6.7 Update670-201810221
VMwareESXi Version6.7 Update670-201810222
VMwareESXi Version6.7 Update670-201810223
VMwareESXi Version6.7 Update670-201810224
VMwareESXi Version6.7 Update670-201810225
VMwareESXi Version6.7 Update670-201810226
VMwareESXi Version6.7 Update670-201810227
VMwareESXi Version6.7 Update670-201810228
VMwareESXi Version6.7 Update670-201810229
VMwareESXi Version6.7 Update670-201810230
VMwareESXi Version6.7 Update670-201810231
VMwareESXi Version6.7 Update670-201810232
VMwareESXi Version6.7 Update670-201810233
VMwareESXi Version6.7 Update670-201810234
VMwareESXi Version6.7 Update670-201811001
VMwareESXi Version6.7 Update670-201901001
VMwareESXi Version6.7 Update670-201901401
VMwareESXi Version6.7 Update670-201901402
VMwareESXi Version6.7 Update670-201901403
VMwareESXi Version6.7 Update670-201904201
VMwareESXi Version6.7 Update670-201904202
VMwareESXi Version6.7 Update670-201904203
VMwareESXi Version6.7 Update670-201904204
VMwareESXi Version6.7 Update670-201904205
VMwareESXi Version6.7 Update670-201904206
VMwareESXi Version6.7 Update670-201904207
VMwareESXi Version6.7 Update670-201904208
VMwareESXi Version6.7 Update670-201904209
VMwareESXi Version6.7 Update670-201904210
VMwareESXi Version6.7 Update670-201904211
VMwareESXi Version6.7 Update670-201904212
VMwareESXi Version6.7 Update670-201904213
VMwareESXi Version6.7 Update670-201904214
VMwareESXi Version6.7 Update670-201904215
VMwareESXi Version6.7 Update670-201904216
VMwareESXi Version6.7 Update670-201904217
VMwareESXi Version6.7 Update670-201904218
VMwareESXi Version6.7 Update670-201904219
VMwareESXi Version6.7 Update670-201904220
VMwareESXi Version6.7 Update670-201904221
VMwareESXi Version6.7 Update670-201904222
VMwareESXi Version6.7 Update670-201904223
VMwareESXi Version6.7 Update670-201904224
VMwareESXi Version6.7 Update670-201904225
VMwareESXi Version6.7 Update670-201904226
VMwareESXi Version6.7 Update670-201904227
VMwareESXi Version6.7 Update670-201904228
VMwareESXi Version6.7 Update670-201904229
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.601
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 1.6 5.2
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.